Page MenuHomeVyOS Platform
Feed All Stories

Aug 18 2022

aserkin added a comment to T4617: VRF specification is needed for telegraf prometheus-client listen-address <address> .

The only way to start telegraf with ip vrf exec i found - is to comment out
#User=telegraf
in /etc/systemd/system/vyos-telegraf.service and
chown root:root /run/telegraf

Aug 18 2022, 11:07 AM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4623: Add show conntrack statistics.
Aug 18 2022, 10:09 AM · VyOS Rolling
Viacheslav added a parent task for T4623: Add show conntrack statistics: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Aug 18 2022, 10:09 AM · VyOS 1.4 Sagitta
Viacheslav created T4623: Add show conntrack statistics.
Aug 18 2022, 10:02 AM · VyOS 1.4 Sagitta

Aug 17 2022

sarthurdev added a comment to T4612: Support arbitrary netmasks in firewall rules.

Not supported at the moment, but we can look into adding it for both ipv4/v6 in 1.4

Aug 17 2022, 8:05 PM · VyOS 1.4 Sagitta
sarthurdev added a comment to T4605: Firewall change default table names.

While I'm for changing to prefixed tables, I think the issue of tailscale and custom apps should fall under the accepted risk of running custom scripts outside of the config.

Aug 17 2022, 8:02 PM · VyOS 1.4 Sagitta
sarthurdev added a comment to T4610: Firewall with 20K entries cannot load after reboot.

Any config available to test against?

Aug 17 2022, 7:53 PM · VyOS 1.4 Sagitta
sempervictus added a comment to T3896: Extend ocserv support to allow for per-group configs.

I think that having the configuration stored exclusively in files outside the config file breaks portability as exporting system state through # show | commands won't produce an output sufficient for full state backup of a device.
If the configuration attributes were all in the CLI which then generated the relevant files in the FS, that would address the stateless backing filesystem concern by centralizing the device config as the source of truth.
@SquirePug - could you possibly provide a link to or the contents of the changes you made? Thanks

Aug 17 2022, 4:41 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4622: Firewall allow drop packets by TCP MSS size.
Aug 17 2022, 4:12 PM · VyOS 1.4 Sagitta
Viacheslav renamed T4622: Firewall allow drop packets by TCP MSS size from Firewall allow drop packets by TCP MSS to Firewall allow drop packets by TCP MSS size.
Aug 17 2022, 4:11 PM · VyOS 1.4 Sagitta
Viacheslav created T4622: Firewall allow drop packets by TCP MSS size.
Aug 17 2022, 3:37 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4619: Static arp is not set if another entry is present from Open to Needs testing.
Aug 17 2022, 3:22 PM · VyOS 1.4 Sagitta
Viacheslav moved T4480: add an ability to configure squid acl safe ports and acl ssl safe ports from Open to Finished on the VyOS 1.4 Sagitta board.
Aug 17 2022, 3:20 PM · VyOS 1.4 Sagitta
Viacheslav moved T4598: nat66 - Add exclude options from Open to Finished on the VyOS 1.4 Sagitta board.
Aug 17 2022, 3:19 PM · VyOS 1.4 Sagitta
n.fort closed T4480: add an ability to configure squid acl safe ports and acl ssl safe ports as Resolved.
Aug 17 2022, 1:47 PM · VyOS 1.4 Sagitta
n.fort closed T4598: nat66 - Add exclude options, a subtask of T2518: Add support for IPv6 NAT (NPTv6), as Resolved.
Aug 17 2022, 1:46 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort closed T4598: nat66 - Add exclude options as Resolved.
Aug 17 2022, 1:46 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4601: dhcp : relay agent IP address issue..

@m.korobeinikov Could you check it in 1.3

Aug 17 2022, 11:31 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav moved T4618: Traffic policy not set on virtual interfaces from Open to Finished on the VyOS 1.4 Sagitta board.
Aug 17 2022, 9:49 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T4618: Traffic policy not set on virtual interfaces.

PR for 1.3.2 https://github.com/vyos/vyatta-cfg-qos/pull/16

Aug 17 2022, 9:49 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T4621: OpenConnect group selection.

The similar request T3896

Aug 17 2022, 1:49 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Aug 16 2022

sempervictus updated subscribers of T4621: OpenConnect group selection.
Aug 16 2022, 8:39 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sempervictus created T4621: OpenConnect group selection.
Aug 16 2022, 8:38 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po edited projects for T4538: Macsec does not work correctly when the interface status changes., added: VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus (1.3.2).
Aug 16 2022, 6:06 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po moved T4260: Extend vyos.configdict.node_changed() to support recursiveness from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.2) board.
Aug 16 2022, 6:06 PM · VyOS 1.3 Equuleus (1.3.2)
c-po moved T4537: MACsec not working with cipher gcm-aes-256 from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.2) board.
Aug 16 2022, 6:06 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po closed T4537: MACsec not working with cipher gcm-aes-256 as Resolved.
Aug 16 2022, 6:05 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXd69b7989620d: upnp: T4613: Verify listen key in dictionary.
Aug 16 2022, 5:24 PM
GitHub <[email protected]> committed rVYOSONEX1f880973e221: Merge pull request #1475 from sever-sever/T4613 (authored by c-po).
Aug 16 2022, 5:24 PM
GitHub <[email protected]> committed rVYOSONEX9c9e7618cdc5: T4619: Replacing instead of adding a static arp entry (authored by daniil).
Aug 16 2022, 5:22 PM
GitHub <[email protected]> committed rVYOSONEX8093312a899b: Merge pull request #1474 from DaniilHarun/current (authored by c-po).
Aug 16 2022, 5:22 PM
aserkin added a comment to T4617: VRF specification is needed for telegraf prometheus-client listen-address <address> .

Manual start of telegraf works for me

Aug 16 2022, 4:46 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4620: UPnP does not work due to incorrect template.

PR https://github.com/vyos/vyos-1x/pull/1476

Aug 16 2022, 4:30 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4611: UPnP rule IP should be a prefix instead of an address.

PR https://github.com/vyos/vyos-1x/pull/1476

Aug 16 2022, 4:30 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4611: UPnP rule IP should be a prefix instead of an address from Open to In progress.
Aug 16 2022, 4:11 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4620: UPnP does not work due to incorrect template.
Aug 16 2022, 3:54 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4620: UPnP does not work due to incorrect template from Open to In progress.
Aug 16 2022, 3:52 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4611: UPnP rule IP should be a prefix instead of an address.

It seems UPnP rules doesn't work at all task T4620

Aug 16 2022, 3:52 PM · VyOS 1.4 Sagitta
Viacheslav created T4620: UPnP does not work due to incorrect template.
Aug 16 2022, 3:51 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4611: UPnP rule IP should be a prefix instead of an address.

@patrickli Could you send a real example? In your example, port ranges are incorrect also it is not all required UPnP configuration
If you sent all UPnP configuration, it already has been done :)
I'm not a UPnP person, so I ask for some examples.

Aug 16 2022, 3:23 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4613: UPnP configuration without listen option fail.

PR https://github.com/vyos/vyos-1x/pull/1475

Aug 16 2022, 3:04 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4613: UPnP configuration without listen option fail from Open to In progress.
Aug 16 2022, 2:29 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4613: UPnP configuration without listen option fail.
Aug 16 2022, 2:28 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4617: VRF specification is needed for telegraf prometheus-client listen-address <address> .

I tried to add vrf, but it requires some permissions, service is not starting

diff --git a/data/templates/monitoring/override.conf.j2 b/data/templates/monitoring/override.conf.j2
index 9f1b4ebe..63e479af 100644
--- a/data/templates/monitoring/override.conf.j2
+++ b/data/templates/monitoring/override.conf.j2
@@ -1,7 +1,10 @@
+{% set vrf_command = 'ip vrf exec ' ~ vrf ~ ' ' if vrf is vyos_defined else '' %}
 [Unit]
 After=vyos-router.service
 ConditionPathExists=/run/telegraf/vyos-telegraf.conf
 [Service]
+ExecStart=
+ExecStart={{ vrf_command }}/usr/bin/telegraf -config /run/telegraf/vyos-telegraf.conf -config-directory /etc/telegraf/telegraf.d $TELEGRAF_OPTS
 Environment=INFLUX_TOKEN={{ influxdb.authentication.token }}
 CapabilityBoundingSet=CAP_NET_RAW CAP_NET_ADMIN CAP_SYS_ADMIN
 AmbientCapabilities=CAP_NET_RAW CAP_NET_ADMIN
diff --git a/interface-definitions/service-monitoring-telegraf.xml.in b/interface-definitions/service-monitoring-telegraf.xml.in
index 36f40a53..dc014ee1 100644
--- a/interface-definitions/service-monitoring-telegraf.xml.in
+++ b/interface-definitions/service-monitoring-telegraf.xml.in
@@ -306,6 +306,7 @@
                   </leafNode>
                 </children>
               </node>
+              #include <include/interface/vrf.xml.i>
             </children>
           </node>
         </children>
Aug 16 2022, 1:40 PM · VyOS 1.4 Sagitta
jestabro removed a project from T3993: Extend HTTP API GraphQL support: VyOS 1.3 Equuleus.
Aug 16 2022, 1:26 PM · VyOS 1.4 Sagitta
jestabro moved T3993: Extend HTTP API GraphQL support from Open to In Progress on the VyOS 1.4 Sagitta board.
Aug 16 2022, 1:25 PM · VyOS 1.4 Sagitta
jestabro edited projects for T3993: Extend HTTP API GraphQL support, added: VyOS 1.4 Sagitta, VyOS 1.3 Equuleus; removed VyOS 1.3 Equuleus (1.3.2).
Aug 16 2022, 1:25 PM · VyOS 1.4 Sagitta
jestabro closed T4413: Add an API endpoint with basic system stats as Resolved.
Aug 16 2022, 1:22 PM · VyOS 1.4 Sagitta
daniil updated the task description for T4619: Static arp is not set if another entry is present.
Aug 16 2022, 1:07 PM · VyOS 1.4 Sagitta
daniil added a comment to T4619: Static arp is not set if another entry is present.

PR https://github.com/vyos/vyos-1x/pull/1474

Aug 16 2022, 12:53 PM · VyOS 1.4 Sagitta
daniil created T4619: Static arp is not set if another entry is present.
Aug 16 2022, 12:36 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4617: VRF specification is needed for telegraf prometheus-client listen-address <address> .

As we have one config file for all plugins, as we start only one telegraf process, I guess it should be global telegraf option set service monitoring telegraf vrf <vrf-name>

Aug 16 2022, 12:32 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4596: "show openconnect-server sessions" command does not work in the openconnect module, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from In progress to Needs testing.
Aug 16 2022, 11:58 AM · VyOS Rolling
Viacheslav changed the status of T4596: "show openconnect-server sessions" command does not work in the openconnect module from In progress to Needs testing.
Aug 16 2022, 11:58 AM · VyOS 1.4 Sagitta
dmbaturin committed rVYOSONEX8f63565add6b: syslog: T4039: Add protocol23format logging for UDP (authored by Viacheslav).
Aug 16 2022, 11:56 AM
GitHub <[email protected]> committed rVYOSONEX4d845cc36822: Merge pull request #1473 from dmbaturin/T4039-equ (authored by Viacheslav).
Aug 16 2022, 11:56 AM
Viacheslav added a comment to T4618: Traffic policy not set on virtual interfaces.

PR https://github.com/vyos/vyatta-cfg-qos/pull/14

Aug 16 2022, 11:48 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav changed the status of T4618: Traffic policy not set on virtual interfaces from Open to In progress.
Aug 16 2022, 11:31 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
dmbaturin closed T4592: macsec: can not create two interfaces using the same source-interface as Resolved.
Aug 16 2022, 10:14 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav assigned T4601: dhcp : relay agent IP address issue. to Unknown Object (User).
Aug 16 2022, 9:58 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav changed the status of T4601: dhcp : relay agent IP address issue. from Confirmed to Needs testing.
Aug 16 2022, 9:58 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
daniil created T4618: Traffic policy not set on virtual interfaces.
Aug 16 2022, 9:52 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po committed rVYOSONEX6b3c359ed099: Debian: T4584: remove version number from hostap package requirement.
Aug 16 2022, 8:29 AM
GitHub <[email protected]> committed rVYOSONEXa8793122bb22: Merge pull request #1472 from c-po/debian-t4584-equuleus (authored by dmbaturin).
Aug 16 2022, 8:29 AM
Viacheslav committed rVYOSONEX1bd3a9635a5f: ocserv: T4596: Rewrite show openconnect sessions op-mode.
Aug 16 2022, 6:27 AM
GitHub <[email protected]> committed rVYOSONEXa21669ee5c87: Merge pull request #1462 from sever-sever/T4596 (authored by c-po).
Aug 16 2022, 6:27 AM
c-po committed rVYOSONEX681bdf2946d1: Debian: T4584: remove version number from hostap package requirement.
Aug 16 2022, 6:23 AM
c-po moved T4584: hostap: create custom package build from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.2) board.
Aug 16 2022, 6:19 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po closed T4584: hostap: create custom package build, a subtask of T4537: MACsec not working with cipher gcm-aes-256, as Resolved.
Aug 16 2022, 6:19 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po closed T4584: hostap: create custom package build as Resolved.
Aug 16 2022, 6:19 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
GitHub <[email protected]> committed rVYOSONEX160262edaf1b: dhcp-relay: T4601: restart dhcp relay-agent (authored by mkorobeinikov <[email protected]>).
Aug 16 2022, 5:02 AM
GitHub <[email protected]> committed rVYOSONEX1e81eec1b916: Merge pull request #1471 from mkorobeinikov/current (authored by c-po).
Aug 16 2022, 5:02 AM
Unknown Object (User) changed the status of T4601: dhcp : relay agent IP address issue. from Open to Confirmed.

https://github.com/vyos/vyos-1x/pull/1471

Aug 16 2022, 12:15 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta

Aug 15 2022

aserkin created T4617: VRF specification is needed for telegraf prometheus-client listen-address <address> .
Aug 15 2022, 10:22 PM · VyOS 1.4 Sagitta
c-po added a comment to T4616: openconnect: KeyError: 'local_users'.

PR https://github.com/vyos/vyos-1x/pull/1470

Aug 15 2022, 6:55 PM · VyOS 1.3 Equuleus (1.3.2)
c-po claimed T4616: openconnect: KeyError: 'local_users'.
Aug 15 2022, 6:51 PM · VyOS 1.3 Equuleus (1.3.2)
c-po edited projects for T4616: openconnect: KeyError: 'local_users', added: VyOS 1.3 Equuleus (1.3.3); removed VyOS 1.3 Equuleus.
Aug 15 2022, 6:50 PM · VyOS 1.3 Equuleus (1.3.2)
c-po created T4616: openconnect: KeyError: 'local_users'.
Aug 15 2022, 6:50 PM · VyOS 1.3 Equuleus (1.3.2)
c-po added a comment to T4614: OpenConnect split-dns directive.

PR for VyOS 1.3 https://github.com/vyos/vyos-1x/pull/1470

Aug 15 2022, 6:47 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po moved T4614: OpenConnect split-dns directive from Open to Finished on the VyOS 1.4 Sagitta board.
Aug 15 2022, 6:17 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po committed rVYOSONEXe41685a2f56c: ocserv: openconnect: T4614: add support for split-dns.
Aug 15 2022, 6:17 PM
c-po committed rVYOSONEXbd102eac6d0c: smoketest: ocserv: implement config file validation.
Aug 15 2022, 6:17 PM
c-po committed rVYOSONEX6e82d5d87f0f: ocserv: T4333: migrate to new vyos_defined Jinja2 test.
Aug 15 2022, 6:17 PM
c-po closed T4565: vlan aware bridge not working as Resolved.
Aug 15 2022, 5:47 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.3 Equuleus (1.3.2)
c-po moved T4565: vlan aware bridge not working from In Progress to Finished on the VyOS 1.3 Equuleus (1.3.2) board.
Aug 15 2022, 5:47 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.3 Equuleus (1.3.2)
c-po edited projects for T4565: vlan aware bridge not working , added: VyOS 1.3 Equuleus (1.3.2); removed VyOS 1.3 Equuleus (1.3.3).
Aug 15 2022, 5:47 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.3 Equuleus (1.3.2)
c-po committed rVYOSONEX488024e698ac: macsec: T4537: support online ciper and source-interface re-configuration.
Aug 15 2022, 5:44 PM
c-po committed rVYOSONEXfd5adb0136aa: macsec: T4537: allow 32-byte keys for gcm-aes-256.
Aug 15 2022, 5:44 PM
c-po committed rVYOSONEX66c1fbe7665f: macsec: T2023: fixup systemd unit description.
Aug 15 2022, 5:44 PM
c-po committed rVYOSONEXfdc7814f12bc: macsec: T4537: restart wpa_supplicant on error.
Aug 15 2022, 5:44 PM
c-po committed rVYOSONEX52b4b47f9e24: macsec: T4537: supply PID path via systemd service file to daemon.
Aug 15 2022, 5:44 PM
c-po committed rVYOSONEXdc41d55eba5e: macsec: T4537: remove debug falg "-d" from systemd service file.
Aug 15 2022, 5:44 PM
c-po committed rVYOSONEXae139a68883c: smoketest: macsec: T4537: verify macsec_csindex.
Aug 15 2022, 5:44 PM
c-po committed rVYOSONEX99777682f8bc: macsec: T4537: add missing macsec_csindex option to support GCM-AES-256.
Aug 15 2022, 5:44 PM
c-po committed rVYOSONEX922871b4dc41: macsec: T4592: can not create two interfaces using the same source-interface.
Aug 15 2022, 5:44 PM
c-po committed rVYOSONEX84f96733bb40: smoketest: macsec: T4537: validate macsec_csindex for both AES-GCM-128 and AES….
Aug 15 2022, 5:44 PM
c-po committed rVYOSONEXdf704a7cb884: macsec: T4537: macsec_csindex can be set even without encryption.
Aug 15 2022, 5:44 PM
GitHub <[email protected]> committed rVYOSONEX50bdb0e9e450: Merge pull request #1469 from c-po/macsec-equuleus (authored by c-po).
Aug 15 2022, 5:44 PM
aserkin renamed T4615: vpn sessions-columns configuration needed from vpn session-columns configuration needed to vpn sessions-columns configuration needed.
Aug 15 2022, 5:40 PM · VyOS 1.5 Circinus
aserkin created T4615: vpn sessions-columns configuration needed.
Aug 15 2022, 5:38 PM · VyOS 1.5 Circinus